# 每日安全资讯(2026-07-30) - Private Feed for M09Ic - [ ] [bolucat released 202607292125 at bolucat/Archive](https://github.com/bolucat/Archive/releases/tag/202607292125) - [ ] [INotGreen starred Vincentwei1021/video-shotcraft](https://github.com/Vincentwei1021/video-shotcraft) - [ ] [chainreactors released v0.0.0-nightly.20260729 at chainreactors/aiscan](https://github.com/chainreactors/aiscan/releases/tag/v0.0.0-nightly.20260729) - [ ] [BeichenDream starred Noelo-Lab/kuna](https://github.com/Noelo-Lab/kuna) - [ ] [killeven starred can1357/oh-my-pi](https://github.com/can1357/oh-my-pi) - [ ] [esrrhs contributed to esrrhs/fakelua](https://github.com/esrrhs/fakelua/pull/288) - [ ] [future-architect released v0.40.0-rc.1 at future-architect/vuls](https://github.com/future-architect/vuls/releases/tag/v0.40.0-rc.1) - [ ] [BeichenDream starred neocanable/garlic](https://github.com/neocanable/garlic) - [ ] [ZeddYu starred openai/codex-security](https://github.com/openai/codex-security) - [ ] [gh0stkey starred zedless-editor/zedless](https://github.com/zedless-editor/zedless) - [ ] [Mr-xn starred lmn1919/dompdf.js](https://github.com/lmn1919/dompdf.js) - [ ] [ring04h starred openai/codex-security](https://github.com/openai/codex-security) - [ ] [FunnyWolf starred microsoft/agent-governance-toolkit](https://github.com/microsoft/agent-governance-toolkit) - [ ] [bolucat released 202607290513 at bolucat/Archive](https://github.com/bolucat/Archive/releases/tag/202607290513) - [ ] [gh0stkey starred MoonshotAI/Kimi-K3](https://github.com/MoonshotAI/Kimi-K3) - A Few Thoughts on Cryptographic Engineering - [ ] [Some thoughts about Anthropic’s new cryptanalysis results](https://blog.cryptographyengineering.com/2026/07/29/some-notes-about-anthropics-new-results/) - Tenable Blog - [ ] [Coordinated “cyberattack” on Minnesota water utilities: What you need to know](https://www.tenable.com/blog/coordinated-cyberattack-on-minnesota-water-utilities-what-you-need-to-know) - 安全客-有思想的安全新媒体 - [ ] [OpenAI 开源 Codex Security CLI:用于发现、验证和修复安全漏洞](https://www.anquanke.com/post/id/315867) - Der Flounder - [ ] [Creating a Jamf Pro API Role with all available API privileges using a Jamf Pro user account with Administrator account privileges](https://derflounder.wordpress.com/2026/07/29/creating-a-jamf-pro-api-role-with-all-available-api-privileges-using-a-jamf-pro-user-account-with-administrator-account-privileges/) - Recent Commits to cve:main - [ ] [Update Wed Jul 29 11:48:08 UTC 2026](https://github.com/trickest/cve/commit/b349e2ac98435c78e6eec698cf95df82dacb0ca1) - SecWiki News - [ ] [SecWiki News 2026-07-29 Review](http://www.sec-wiki.com/?2026-07-29) - Doonsec's feed - [ ] [通知 | 网安标委就《网络安全标准实践指南——智能体交互安全要求(征求意见稿)》等2项网络安全标准实践指南公开征求意见(附下载)](https://mp.weixin.qq.com/s/M8nSmKPbzzUD-wlUZKPdog) - [ ] [火山引擎开源 Agent 驱动的搜索自迭代技术](https://mp.weixin.qq.com/s/sJH9QeD71BWGIGDaOhaUvg) - [ ] [征求意见稿丨网络安全标准实践指南——网络数据安全风险评估采信指南(附下载)](https://mp.weixin.qq.com/s/pRlVpWS5hThxTM4kNWA7PA) - [ ] [OpenAI失控模型在互联网上“游荡”了4天,并袭击了另一家AI公司](https://mp.weixin.qq.com/s/fCA4HjkBkZqeEq0xwb1E-A) - [ ] [招募令|「澳門網絡攻防精英培訓」開始報名啦](https://mp.weixin.qq.com/s/CnFv9JJadrWGLPld8jF0xw) - [ ] [关于第二届世界人形机器人运动会场景赛比赛安排的通知](https://mp.weixin.qq.com/s/EVFNkLwnBc3pzBFmEv4e2A) - [ ] [开展“银狐”木马专项打击行动并公开征集威胁信息线索,中国互联网网络安全威胁治理联盟发布公告](https://mp.weixin.qq.com/s/So-BHkE1XhcP5jkeYgPWxw) - [ ] [《网络安全标准实践指南——智能体交互安全要求(征求意见稿)》等2项网络安全标准实践指南公开征求意见](https://mp.weixin.qq.com/s/1ifZda2_Y5MSHfDrWMaApA) - [ ] [聚焦6个方向,2026年工业和信息化领域创新任务揭榜挂帅工作启动](https://mp.weixin.qq.com/s/53HMKzwpXBBPZQvfZYz7lw) - [ ] [OpenAI 代理在 Hugging Face 泄露事件中,在四个服务中使用了暴露的凭证](https://mp.weixin.qq.com/s/-UY_HbxxIgI3nNXROdgf_w) - [ ] [关于“FakeSvc”挖矿组织大规模传播恶意程序的风险提示](https://mp.weixin.qq.com/s/rk5QHemIRTvjSAixGu61Xg) - [ ] [阿里云联动百位企业安全专家,共识Agent防御最佳实践](https://mp.weixin.qq.com/s/zdEkLJbIGeycPaX-zR6zmA) - [ ] [三位一体筑牢商业秘密保护防线](https://mp.weixin.qq.com/s/md8NkNdulcGglIWAkHoJyA) - [ ] [汽车网络安全:SHA算法详细解析](https://mp.weixin.qq.com/s/o5mqG_6yFlAcnCDFdflbXQ) - [ ] [展位售出过半!AutoSec 2026第十届中国汽车网络安全周展位告急,优质席位速抢](https://mp.weixin.qq.com/s/65OpDCRl0CghZhBY5_RSiw) - [ ] [宝马拟在德国裁员数千人,通过自愿离职计划削减成本,该方案预计10月启动,并持续至2027年](https://mp.weixin.qq.com/s/9O6RpJ28cvdMKAqXJWwqvQ) - [ ] [AI驱动安全,梆梆安全连续实力登榜《网络安全企业100强》](https://mp.weixin.qq.com/s/ZcKVxajhxQJKDqpGTNMysw) - [ ] [密评专栏丨TLCP协议概述](https://mp.weixin.qq.com/s/JbZo_7UIiann_145aL1LrA) - [ ] [网络安全从入门到精通(超详细)学习路线!](https://mp.weixin.qq.com/s/ZoNQlZBJH9ozT-7UtOf6CQ) - [ ] [从一次 TeamCity 认证绕过,看 CI/CD 系统最危险的信任边界](https://mp.weixin.qq.com/s/Oe4c_NYcFvyRuP0uXOWRqA) - [ ] [专家解读|为小型个人信息处理者合理松绑减负 推进个人信息处理活动包容审慎监管](https://mp.weixin.qq.com/s/kNMuVML4DAUJXV29KMmzYQ) - [ ] [运营商视角的网络攻防发展——从网络防护到数字基座的安全重塑](https://mp.weixin.qq.com/s/daWFEQHyzxP2mjkPyLWb8g) - [ ] [会议预告 | 第一届CCF网络与系统安全大会嘉宾阵容揭晓](https://mp.weixin.qq.com/s/3KmL3ZWPoQJ9lyERWPz6vg) - [ ] [本周回顾:失控AI代理、Check Point漏洞利用、Slopsquatting、ClickFix诱饵及其他事件](https://mp.weixin.qq.com/s/qn1BBn5wKtx6gfW0MForbw) - [ ] [HuggingFace首次披露AI入侵全量细节](https://mp.weixin.qq.com/s/H1ggn-0u_T-PpjVRszTuTw) - [ ] [南昌局集团公司网络安全实战攻防演训及竞赛技术支持服务服务项目二次竞争性谈判采购公告](https://mp.weixin.qq.com/s/f6aCcvjvHhu_e-skNAHkWw) - [ ] [火热报名中 | 2026年福建省信息通信行业职业技能竞赛](https://mp.weixin.qq.com/s/wCmrjn86Gx_Jszq-s--G2Q) - [ ] [倒计时3天|第二届OpenHarmony CTF(Capture The Flaw)智能漏洞挖掘赛](https://mp.weixin.qq.com/s/WuqgVgPAmYCfs3xlv_jaUg) - [ ] [第四届“熵密杯”密码安全挑战赛暨2026密码安全论坛成功举办](https://mp.weixin.qq.com/s/btIeFR5s5CBcRJ-w4-N2qA) - [ ] [关于开展网络和数据安全赛事平台能力检测服务的通知](https://mp.weixin.qq.com/s/KOiMRuzjMjOYIEoYdan2rQ) - [ ] [一图读懂“才聚八闽”系列赛事获奖项目落地福州支持方案](https://mp.weixin.qq.com/s/2aIJ3p1SfFY4gQHNGeUCYQ) - [ ] [关于第九届西湖论剑数据要素与数据安全创新实践征集活动延长征集期的公告](https://mp.weixin.qq.com/s/z7JCyQopaEJ-fjCOrwuf5A) - [ ] [2026黄鹤杯网络安全人才创新大赛学生组(失序货栈)](https://mp.weixin.qq.com/s/2EFp3vX5SOKBlEIj_d_SAQ) - [ ] [焦点访谈:聚焦“短视频虚假摆拍乱象”](https://mp.weixin.qq.com/s/3FOlNbS_Nqynvnq2xxjsxg) - [ ] [OpenAI开源Codex Security CLI:用于发现、验证和修复安全漏洞](https://mp.weixin.qq.com/s/nnWfsr1tVIhdedn-oUgiSw) - [ ] [邀请函丨CISP 注册信息安全专业人员认证培训一合规刚需丨持证上岗丨职称等同丨地方补贴丨](https://mp.weixin.qq.com/s/gX2FFE7Ve2lSv8dGXpscFQ) - [ ] [未成年人个人信息保护典型案例集](https://mp.weixin.qq.com/s/VGv0qRA7LD8vK7ClRo0MeQ) - [ ] [主机加固的核查,到底卡在哪一环?](https://mp.weixin.qq.com/s/VpNX0MxDaGT6pLxhmr_Ejg) - [ ] [网络安全日报 | 2026-07-29](https://mp.weixin.qq.com/s/OUB6pFLyumNyI__SOo9Inw) - [ ] [黑客的漏洞监控平台,随时可能失效](https://mp.weixin.qq.com/s/HqYi_jNztyYug4DXLagQqA) - [ ] [GPT-5.6自主“破狱”!AI不仅学会了挖掘0-day漏洞,还洗劫了Hugging Face……](https://mp.weixin.qq.com/s/JEvGTDoJwSjmiJ9_6TOJsw) - [ ] [天融信:AI驱动医疗数据安全运营体系,实现从合规治理到智能运营](https://mp.weixin.qq.com/s/cBx4O4W5Ma19tpZHUZmkZA) - [ ] [授权培训机构2026年8月CISP培训开班计划公告](https://mp.weixin.qq.com/s/C_TAQaBJ11NpgWZM0zbZRA) - [ ] [AI代理全面渗透,企业安全治理是否到位](https://mp.weixin.qq.com/s/BTHh3Gn8IuU6S-sNaxcQ_w) - [ ] [One-Fox零基础培训计划(二期本周开班),带你从配置环境到实战攻防](https://mp.weixin.qq.com/s/vWmmoD4BLfima-N58YQBtg) - [ ] [固态硬盘健康检测,在它出问题之前,看看还剩多少寿命](https://mp.weixin.qq.com/s/9xm_XhJtJR09O2kVdER2vA) - [ ] [清朗\"暑期专项来了,做未成年个人信息合规的朋友都在翻这本手册](https://mp.weixin.qq.com/s/AJT9i7KSzOB0Mw2OkLQkiQ) - [ ] [7月社区投稿活动 | 漏洞挖掘/AI渗透](https://mp.weixin.qq.com/s/faKQy_zqQn0UyQakkYz-eA) - [ ] [Word Copilot 上新模型 Claude Opus 5](https://mp.weixin.qq.com/s/4sejhiTP_h3y8z_tiI1mpA) - [ ] [ChatGPT 5.6 最新模型 140 充值](https://mp.weixin.qq.com/s/Z1ojF8rp_3mhjvzGkKHRLA) - [ ] [北京大学|软件与微电子学院博士生论文被体系结构领域国际顶级会议ISCA 2026录用](https://mp.weixin.qq.com/s/gyWqN4wKOxi1BVZMeNN57w) - [ ] [iOS 26.6正式版,哪些系统不用更新,哪些系统必更?](https://mp.weixin.qq.com/s/svlaaW2TEi-hTMB9rNQ_sA) - [ ] [建行上海分行申请AI创新应用,有望提升信用卡营销响应率等](https://mp.weixin.qq.com/s/A92EOQU-p-fH7WfIe5fkDw) - [ ] [格物致知xa0研发有格 |xa0默安科技正式发布 AI 原生研发治理平台](https://mp.weixin.qq.com/s/Fil95R7Q0hcEyIbDwyWS5w) - [ ] [永别啦!网贷信用卡大结清:央国企、事业编、公务员、上市职工一招清零负债](https://mp.weixin.qq.com/s/BKJ1sMoZnoK1pEFBwJeBVg) - [ ] [浙江、山东非公企业党组织书记联合示范培训班莅临安恒信息参观调研](https://mp.weixin.qq.com/s/mmYC5iwcD4j1vmbsADz4Zw) - [ ] [好好好](https://mp.weixin.qq.com/s/dH5T3u8ev6FZf_FH8Z0dgA) - [ ] [《信息化项目造价咨询服务 标准体系框架》(T/SCSIA 0019-2025)联合发布(附全文)](https://mp.weixin.qq.com/s/R7MvlX6lTYgintzDxzeUsQ) - [ ] [AI 全自动化渗透管理系统 | ARTEX](https://mp.weixin.qq.com/s/PrCKOBDW_pE-dN1dn0i8kw) - [ ] [“系统正在维护” 影子资产实战思路](https://mp.weixin.qq.com/s/EL67pUvwu3c8fGvDIORb8g) - [ ] [OpenAI 开源了Codex Security CLI](https://mp.weixin.qq.com/s/XbMvQdw4TLcgfqIWIpG85Q) - [ ] [我就靠这3句SQL,搞定了leader要的所有数据](https://mp.weixin.qq.com/s/MgvagQW0fofKNBsoE7bTqQ) - [ ] [Fastjson2 AutoType 安全问题确认:现有版本尚无正式修复,公开 EXP 到底能走多远](https://mp.weixin.qq.com/s/6Ph43vq3XrBj5n3s21Cw_w) - [ ] [网安AI速报 | 2026.07.29](https://mp.weixin.qq.com/s/PdjRAiq8bEgzmMnLCTN82w) - [ ] [数据中心是如何工作的?](https://mp.weixin.qq.com/s/dQdIq9ItnCzbyrg_ZYcVCQ) - [ ] [百年老字号中医馆的独家药方,差点被U盘拷走......](https://mp.weixin.qq.com/s/lK6jdWhr7C3WuJsJjGy9uA) - [ ] [2026年亚太经合组织(APEC)数字周|安恒信息受邀分享AI安全实践与思考](https://mp.weixin.qq.com/s/85vB5sQJlVMiDo63WAflNA) - [ ] [绿盟科技2027校园招聘提前批正式启动](https://mp.weixin.qq.com/s/9QjtPwmJmaIA2iLb9VnShw) - [ ] [30多w个坑总有适合你上岸的地方](https://mp.weixin.qq.com/s/T9TzeZeWzjxKnt62bo188Q) - [ ] [安全服务的“冰山”:你看到的只是十分之一](https://mp.weixin.qq.com/s/RtKroAZoANuePiK2v-n9cQ) - [ ] [一个网络安全Skill技能库 - 39大模块,195个安全Skills,覆盖完整攻击面与防御面](https://mp.weixin.qq.com/s/UXpSP4cDhDI0qh-Hb31C2A) - [ ] [漏洞通告|Microsoft Office代码执行漏洞(CVE-2026-55022)](https://mp.weixin.qq.com/s/SqsGBVNmPUSUQZYdkxTZag) - [ ] [上海政务单位做等保,这五个坑最容易卡住](https://mp.weixin.qq.com/s/AbQxY6MIKZJUU1YuCp2jXw) - [ ] [一台没打补丁的虚拟机,攻穿了整家企业内网](https://mp.weixin.qq.com/s/pAoU6Yv77cyo5RlBxs8muA) - [ ] [中国网络空间安全协会关基专委会召开“大模型与重要行业领域网络安全”技术研讨会](https://mp.weixin.qq.com/s/6s4zT1V3mxR6Hw2zIKowaQ) - [ ] [OpenAI 的 AI Agent 攻击 Hugging Face:当模型为了通过测试开始入侵真实系统](https://mp.weixin.qq.com/s/fWcrDCy7gd9qZ-l9aeefPw) - [ ] [VulnFlanker 漏洞监测平台 | WatchVuln 高价值漏洞采集与推送](https://mp.weixin.qq.com/s/s1vS1aW6lCzGn1Jd1rKXbw) - [ ] [微信群突现涉密文件?](https://mp.weixin.qq.com/s/IDyVR9rfCunpUABvb8fApQ) - [ ] [美以伊战争的法律和战略反思——胁迫信号、认知战还是全面战争?](https://mp.weixin.qq.com/s/dYCJWfeKhWcUCJMv2P5Jow) - [ ] [高科技套壳伪装数百真实用户!黄牛靠IP、IMEI篡改技术囤积6万张演唱会票狂赚千万](https://mp.weixin.qq.com/s/s8MdoF0HO_ulUH0dnzB5ng) - [ ] [5元手机壳骗走237万保费!运费险诈骗绑定虚拟币洗钱,9人黑产团伙覆灭](https://mp.weixin.qq.com/s/wVBfbBD-8I0ubhyPGfKsxA) - [ ] [市面上所有“代收赚佣金”全是跑分洗钱!新旧套路一次性扒干净](https://mp.weixin.qq.com/s/ItIa_HDwxWgr2kcYeNpNNA) - [ ] [【AI复盘】AI Agent自动化勒索攻击事件](https://mp.weixin.qq.com/s/9lUJ3kOL6OJkkJPx1Wyu-g) - ElcomSoft blog - [ ] [Locked In or Locked Out? Unlocking ZIP, RAR, PDF, and Microsoft Office Passwords](https://blog.elcomsoft.com/2026/07/locked-in-or-locked-out-unlocking-zip-rar-pdf-and-microsoft-office-passwords/) - Microsoft Security Blog - [ ] [Better security starts with better questions](https://www.microsoft.com/en-us/security/blog/2026/07/29/better-security-starts-with-better-questions/) - VMRay - [ ] [Moving Beyond Alert Fatigue: 5 Things About SIEM Alerts Every Security Team Should Know](https://www.vmray.com/siem-alerts-guide/) - Malwarebytes - [ ] [Apple accused of letting fake crypto app steal $1.8 million](https://www.malwarebytes.com/blog/news/2026/07/apple-accused-of-letting-fake-crypto-app-steal-1-8-million) - [ ] [Buying TikTok views or followers? Here’s what you’re really getting](https://www.malwarebytes.com/blog/threat-intel/2026/07/buying-tiktok-views-or-followers-heres-what-youre-really-getting) - [ ] [AI robocalls: Why caller ID is still lying to you](https://www.malwarebytes.com/blog/news/2026/07/ai-robocalls-why-caller-id-is-still-lying-to-you) - [ ] [OpenAI explains how its AI agent breached Hugging Face](https://www.malwarebytes.com/blog/news/2026/07/openai-explains-how-its-ai-agent-breached-hugging-face) - [ ] [We found 120 fake Walmart stores trying to steal your credit card](https://www.malwarebytes.com/blog/scams/2026/07/we-found-120-fake-walmart-stores-trying-to-steal-your-credit-card) - Reverse Engineering - [ ] [It's a pre-auth, stupid!](https://reverse.put.as/2026/07/29/its-a-pre-auth-stupid/) - Horizon3 - [ ] [CVE-2026-6516 | ManageEngine ADAudit Plus Pre-Authentication Remote Code Execution Vulnerability](https://horizon3.ai/attack-research/vulnerabilities/cve-2026-6516/) - [ ] [Horizon3’s NodeZero® AI Hacker Extends Production-Safe Autonomous Pentesting to Web Applications](https://horizon3.ai/news/press-release/nodezero-webapp-launch/) - [ ] [Security Validation Should Begin Where Attackers Begin](https://horizon3.ai/intelligence/blogs/web-application-security-validation/) - Bug Bounty in InfoSec Write-ups on Medium - [ ] [Snowflake SQL Injection via Compile-Time Constant Folding with SYSTEM$WAIT](https://infosecwriteups.com/snowflake-sql-injection-via-compile-time-constant-folding-with-system-wait-81374a58e089?source=rss----7b722bfd1b8d--bug_bounty) - [ ] [Account Takeover Across Multiple Programs via Featurebase Integration](https://infosecwriteups.com/account-takeover-across-multiple-programs-via-featurebase-integration-32214666123e?source=rss----7b722bfd1b8d--bug_bounty) - HackerNews - [ ] [医疗计费公司 MCBS 数据泄露影响 126 万人](http://0.0.0.0:8080/post/64530) - [ ] [无人机软件开发商 CubePilot 遭 DNS 劫持,流量被拦截](http://0.0.0.0:8080/post/64529) - [ ] [JFrog 确认 OpenAI 模型在 Hugging Face 入侵事件前利用了 Artifactory 零日漏洞](http://0.0.0.0:8080/post/64528) - [ ] [24,650 个暴露于互联网的 BMC 在登录前泄露 IPMI 密码哈希](http://0.0.0.0:8080/post/64527) - [ ] [两个被篡改的 joyfill npm 包在导入 Node.js 时运行 RAT](http://0.0.0.0:8080/post/64526) - [ ] [Claude AI 破解后量子测试方案并发现更快的 7 轮 AES 攻击](http://0.0.0.0:8080/post/64525) - 风雪之隅 - [ ] [我的微信公众号](https://www.laruence.com/2026/07/29/6248.html) - rtl-sdr.com - [ ] [Building a $50 BOM Software Defined Radio with a HT9201 20 MHz ADC and an FX2LP USB Controller Clone](https://www.rtl-sdr.com/building-a-50-bom-software-defined-radio-with-a-ht9201-20-mhz-adc-and-an-fx2lp-usb-controller-clone/) - [ ] [Radio Silence: A Native iOS App for Listening to Public KiwiSDRs](https://www.rtl-sdr.com/radio-silence-a-native-ios-app-for-listening-to-public-kiwisdrs/) - [ ] [TunerScope: A Browser App to Help Optimize HDTV Antenna Positioning with an RTL-SDR](https://www.rtl-sdr.com/tunerscope-a-browser-app-to-help-optimize-hdtv-antenna-positioning-with-an-rtl-sdr/) - [ ] [DeepSDR Updates: Live Public Safety Incident Map with an RTL-SDR, Whisper and an LLM](https://www.rtl-sdr.com/deepsdr-updates-live-public-safety-incident-map-with-an-rtl-sdr-whisper-and-an-llm/) - 黑海洋Wiki | AI机器人硬件开发 | 网络安全攻防实战 | 区块链技术文档教程 - 免费资源平台 - [ ] [英国调查微软Microsoft 365订阅涨价问题](https://blog.upx8.com/%E8%8B%B1%E5%9B%BD%E8%B0%83%E6%9F%A5%E5%BE%AE%E8%BD%AFMicrosoft-365%E8%AE%A2%E9%98%85%E6%B6%A8%E4%BB%B7%E9%97%AE%E9%A2%98) - Black Hills Information Security, Inc. - [ ] [Report As You Go: Maintaining Good Documentation for SOC Analysts](https://www.blackhillsinfosec.com/report-as-you-go-soc/) - 绿盟科技技术博客 - [ ] [当员工用AI中转站“顺手”发走内部数据,企业边界正在悄悄失守](https://blog.nsfocus.net/%e5%bd%93%e5%91%98%e5%b7%a5%e7%94%a8ai%e4%b8%ad%e8%bd%ac%e7%ab%99%e9%a1%ba%e6%89%8b%e5%8f%91%e8%b5%b0%e5%86%85%e9%83%a8%e6%95%b0%e6%8d%ae%ef%bc%8c%e4%bc%81%e4%b8%9a%e8%be%b9%e7%95%8c/) - 奇客Solidot–传递最新科技情报 - [ ] [GCC 宣布 AI 政策](https://www.solidot.org/story?sid=84958) - [ ] [微软悄悄在 Windows 11 上安装了 OneDrive Photos](https://www.solidot.org/story?sid=84957) - [ ] [Google 研究未发现有证据显示 AI 将导致大规模自动化以及能取代白领](https://www.solidot.org/story?sid=84956) - [ ] [50 岁以上工人的睡眠危机](https://www.solidot.org/story?sid=84955) - [ ] [美国科技巨头现金流失加速](https://www.solidot.org/story?sid=84954) - [ ] [DeepMind 解散 AlphaFold 项目团队](https://www.solidot.org/story?sid=84953) - [ ] [eBay 支付 5600 万美元和解骚扰跟踪记者案](https://www.solidot.org/story?sid=84952) - [ ] [Swift 天文台拯救任务面临变数](https://www.solidot.org/story?sid=84951) - [ ] [DEF CON 禁止有录像功能的智能眼镜](https://www.solidot.org/story?sid=84950) - [ ] [美国以国家安全理由禁售外国制造的先进机器人](https://www.solidot.org/story?sid=84949) - [ ] [卫星照片确认亚马逊位于巴林的两座数据中心遭到破坏](https://www.solidot.org/story?sid=84948) - 黑鸟 - [ ] [听键盘声就能还原你打的字?无需标注的自监督窃听,正在变成真实隐私威胁](https://mp.weixin.qq.com/s?__biz=MzAxOTM1MDQ1NA==&mid=2451187895&idx=1&sn=f3c98e3bedfced4f2d93024316a4962c) - 雷神众测 - [ ] [雷神众测漏洞周报2026.7.20-2026.7.26](https://mp.weixin.qq.com/s?__biz=MzI0NzEwOTM0MA==&mid=2652503889&idx=1&sn=4a1cc75b84e95e0eca72681aedaadb01) - 安全内参 - [ ] [OpenAI失控模型在互联网上“游荡”了4天,并袭击了另一家AI公司](https://mp.weixin.qq.com/s?__biz=MzI4NDY2MDMwMw==&mid=2247516343&idx=1&sn=05b3383792b82d14b3194c7aee039e50) - [ ] [美国网络司令部通过MDDE项目塑造跨域非动能反导作战能力](https://mp.weixin.qq.com/s?__biz=MzI4NDY2MDMwMw==&mid=2247516343&idx=2&sn=f54a68d3af1a9445c29ad4e36909b4da) - 安全客 - [ ] [OpenAI开源Codex Security CLI:用于发现、验证和修复安全漏洞](https://mp.weixin.qq.com/s?__biz=MzA5ODA0NDE2MA==&mid=2649790293&idx=1&sn=3dafe8f68a7666a50c6edd26cfbe7932) - XCTF联赛 - [ ] [倒计时3天|第二届OpenHarmony CTF(Capture The Flaw)智能漏洞挖掘赛](https://mp.weixin.qq.com/s?__biz=MjM5NDU3MjExNw==&mid=2247516616&idx=1&sn=8e356c728b7dec1f96753f0c92b3ddb7) - 数世咨询 - [ ] [在 Mythos 时代,安全应在运行时进行拦截](https://mp.weixin.qq.com/s?__biz=MzkxNzA3MTgyNg==&mid=2247543622&idx=1&sn=6718a856066c89c5ef9971fae71dcdec) - [ ] [2026Q2风险复盘:银狐诈骗邮件达2896万封,三大风险需警惕!](https://mp.weixin.qq.com/s?__biz=MzkxNzA3MTgyNg==&mid=2247543622&idx=2&sn=0178d0002f363d59552fe0ccb7ec2cbe) - 奇安信威胁情报中心 - [ ] [折腾Huggingface的这届AI糙快猛,隐蔽性才3分——但8.8分够把你打穿了](https://mp.weixin.qq.com/s?__biz=MzI2MDc2MDA4OA==&mid=2247519612&idx=1&sn=40335f5dd3b6e9307ba8f1a5d86c2338) - 天黑说嘿话 - [ ] [Fastjson2 AutoType 安全问题确认:现有版本尚无正式修复,公开 EXP 到底能走多远](https://mp.weixin.qq.com/s?__biz=MzI5NTQ5MTAzMA==&mid=2247486291&idx=1&sn=a02060010a5e026011668cfa2072d079) - 看雪学苑 - [ ] [CAISP认证培训·8月开班!攻防+合规双能力](https://mp.weixin.qq.com/s?__biz=MjM5NTc2MDYxMw==&mid=2458617960&idx=1&sn=b010455c93ab46f6bf19d5d03232bcaf) - [ ] [基于VT EPT的无痕断点无痕hook原理及其应用](https://mp.weixin.qq.com/s?__biz=MjM5NTc2MDYxMw==&mid=2458617960&idx=2&sn=29f97365fe3188b772387e3dbc806c70) - [ ] [速更!iOS 26.6 修复内核代码执行、Root提权等高危漏洞](https://mp.weixin.qq.com/s?__biz=MjM5NTc2MDYxMw==&mid=2458617960&idx=3&sn=90434953831a389eb1c96a400518f879) - 安全圈 - [ ] [【安全圈】Check Point 紧急修复!认证绕过漏洞 PoC 已公开,CVSS 9.3](https://mp.weixin.qq.com/s?__biz=MzIzMzE4NDU1OQ==&mid=2652078064&idx=1&sn=79d6a8b9aa80aaae459d916c7b6cb35a) - [ ] [【安全圈】AI 失控!OpenAI 模型突破隔离入侵 Hugging Face](https://mp.weixin.qq.com/s?__biz=MzIzMzE4NDU1OQ==&mid=2652078064&idx=2&sn=cbd0e3866eb0b17d79e3eadf9bda8aab) - [ ] [【安全圈】Gitea 紧急修复!CVSS 9.8 RCE 漏洞 PoC 已公开](https://mp.weixin.qq.com/s?__biz=MzIzMzE4NDU1OQ==&mid=2652078064&idx=3&sn=305d40c9560536981df8cf7e2f5ab9a5) - 默安科技 - [ ] [格物致知 研发有格 | 默安科技正式发布 AI 原生研发治理平台](https://mp.weixin.qq.com/s?__biz=MzIzODQxMjM2NQ==&mid=2247501919&idx=1&sn=009a7c1943d2fc274ab36005e14d3ca5) - 网络空间安全科学学报 - [ ] [“自主可信计算与新质生产力发展”专题征稿](https://mp.weixin.qq.com/s?__biz=MzI0NjU2NDMwNQ==&mid=2247508028&idx=1&sn=fb86752778de0c02547b8605ed223b89) - [ ] [倒计时30天!15位院士任会议主席!2026科学智能大会前瞻](https://mp.weixin.qq.com/s?__biz=MzI0NjU2NDMwNQ==&mid=2247508028&idx=2&sn=c73611960ad1447b01e5be549c475a6c) - [ ] [2026科学智能大会|学术成果墙报开放征集](https://mp.weixin.qq.com/s?__biz=MzI0NjU2NDMwNQ==&mid=2247508028&idx=3&sn=b8e79ef6225b2aa93d648c50b82fcdbd) - 天御攻防实验室 - [ ] [美国网络司令部“四骑士”](https://mp.weixin.qq.com/s?__biz=MzU0MzgyMzM2Nw==&mid=2247487089&idx=1&sn=2f1627dcfabf0f6d7708a0205804a2d4) - 威努特安全网络 - [ ] [信创背景下,工业安全架构如何实现国产化替换?](https://mp.weixin.qq.com/s?__biz=MzAwNTgyODU3NQ==&mid=2651143263&idx=1&sn=ec1e0e90871f826e0ea856622b31ef35) - 信息安全国家工程研究中心 - [ ] [专家解读|为小型个人信息处理者合理松绑减负 推进个人信息处理活动包容审慎监管](https://mp.weixin.qq.com/s?__biz=MzU5OTQ0NzY3Ng==&mid=2247504543&idx=1&sn=403390fd289c3185071f77b25cde88dd) - 微步在线研究响应中心 - [ ] [原创漏洞 | Apple macOS SMB 内核内存损坏漏洞](https://mp.weixin.qq.com/s?__biz=Mzg5MTc3ODY4Mw==&mid=2247508789&idx=1&sn=1b37679a0aa07a0b0486336a9bf731a1) - 安全牛 - [ ] [31 秒完成攻击闭环:自主 AI 勒索智能体颠覆传统攻防节奏](https://mp.weixin.qq.com/s?__biz=MjM5Njc3NjM4MA==&mid=2651142106&idx=1&sn=bad650cb5fb27eb9db2cc24d3e6353b0) - [ ] [国标委下达 29 项强制国标计划,《智能体应用安全基本要求》在列;Claude共享聊天记录可被Google搜索到,敏感信息暴露| 牛览](https://mp.weixin.qq.com/s?__biz=MjM5Njc3NjM4MA==&mid=2651142106&idx=2&sn=72b55dec1e901b9b60341ded7dbed0c5) - 字节跳动技术团队 - [ ] [火山引擎开源 Agent 驱动的搜索自迭代技术](https://mp.weixin.qq.com/s?__biz=MzI1MzYzMjE0MQ==&mid=2247521040&idx=1&sn=59454cfc3b20a519f2a72e26c0932776) - 电子物证 - [ ] [【欧盟刑事案件电子证据条例的主要内容】](https://mp.weixin.qq.com/s?__biz=MzAwNDcwMDgzMA==&mid=2651049060&idx=1&sn=7c25583df82b3f0db3b9450cf4df4a76) - [ ] [电子证据的现场处置:风险与机遇并存](https://mp.weixin.qq.com/s?__biz=MzAwNDcwMDgzMA==&mid=2651049060&idx=2&sn=f21b846957401f714d6a5e63b2771970) - 火绒安全 - [ ] [火绒强力卸载V1.0.1.0功能升级|优交互 强清理 告别卸载冗余](https://mp.weixin.qq.com/s?__biz=MzI3NjYzMDM1Mg==&mid=2247535759&idx=1&sn=e3f9bb956a62e650ea3c37fca07e8e12) - [ ] [火绒小问答--「个人版」近期top问题解答](https://mp.weixin.qq.com/s?__biz=MzI3NjYzMDM1Mg==&mid=2247535759&idx=2&sn=2fb955c2fc91c3b339a2b05f91ec0852) - [ ] [诚邀渠道合作伙伴共启新征程](https://mp.weixin.qq.com/s?__biz=MzI3NjYzMDM1Mg==&mid=2247535759&idx=3&sn=1b51c109c425012b844953c12aade5b7) - 极客公园 - [ ] [OpenAI 硬件路线图曝光:第一台硬件没有屏幕,手机 2027 上半年量产](https://mp.weixin.qq.com/s?__biz=MTMwNDMwODQ0MQ==&mid=2653111329&idx=1&sn=d3bf26acaa2ec09643a8603b2e1831d9) - [ ] [前 TikTok 产品经理创业,AI 视频共创平台 Wapoo 获千万美元天使融资](https://mp.weixin.qq.com/s?__biz=MTMwNDMwODQ0MQ==&mid=2653111329&idx=2&sn=45edfb10342f1e57d6e2abc905c3ce92) - [ ] [不到一周,众筹 1000 万美金,3D 打印的「Game Changer」,出现了](https://mp.weixin.qq.com/s?__biz=MTMwNDMwODQ0MQ==&mid=2653111313&idx=1&sn=f7a7537f26e9fc6963fa2eba59990cf2) - [ ] [苹果市值首次突破 5 万亿美元;马斯克财富五天缩水 8800 亿;鸿蒙 HarmonyOS 7 百项更新曝光|极客早知道](https://mp.weixin.qq.com/s?__biz=MTMwNDMwODQ0MQ==&mid=2653111297&idx=1&sn=d5b847e0a6d710dfb4422dc710ebe4b8) - 中国信息安全 - [ ] [论坛·原创 | 从效率至上到韧性重构:中美科技博弈的范式转变与全球影响](https://mp.weixin.qq.com/s?__biz=MzA5MzE5MDAzOA==&mid=2664265161&idx=1&sn=94a5ed841cf5253173ac4d55f6aaa88f) - [ ] [通知 | 网安标委就《网络安全标准实践指南——智能体交互安全要求(征求意见稿)》等2项网络安全标准实践指南公开征求意见(附下载)](https://mp.weixin.qq.com/s?__biz=MzA5MzE5MDAzOA==&mid=2664265161&idx=2&sn=580498047274a414a6d2827674b9af92) - [ ] [CNCERT | 关于“FakeSvc”挖矿组织大规模传播恶意程序的风险提示](https://mp.weixin.qq.com/s?__biz=MzA5MzE5MDAzOA==&mid=2664265161&idx=3&sn=356fbb05fe1f5ed77569b18292addf7e) - [ ] [专家解读 | IPv6转向全面赋能和增强内生动力的新征途](https://mp.weixin.qq.com/s?__biz=MzA5MzE5MDAzOA==&mid=2664265161&idx=4&sn=f043de8a459fdf28d3ce1e1e2a58dd4c) - [ ] [专家观点 | 算力产业的发展格局与战略机遇](https://mp.weixin.qq.com/s?__biz=MzA5MzE5MDAzOA==&mid=2664265161&idx=5&sn=33eaa82f725571644ae2191411dc7922) - [ ] [国际 | 一些国家探索打击新型网络诈骗犯罪——来自韩国、荷兰、泰国的实践](https://mp.weixin.qq.com/s?__biz=MzA5MzE5MDAzOA==&mid=2664265161&idx=6&sn=a39c5e9674117e639518ec18002fd4ab) - 安全行者老霍 - [ ] [仅仅看到 AI 智能体并不够,安全团队必须控制它们的行为](https://mp.weixin.qq.com/s?__biz=Mzg3NjU4MDI4NQ==&mid=2247486857&idx=1&sn=10ecc4c36d65f7728cf0343a6977ec3c) - 墨菲安全 - [ ] [8月8日深圳线下沙龙|完整议程及参会信息公布](https://mp.weixin.qq.com/s?__biz=MzkwOTM0MjI5NQ==&mid=2247488592&idx=1&sn=c709703f05e6f3b86c5346a99b8166f3) - 国家互联网应急中心CNCERT - [ ] [关于开展“银狐”木马专项打击行动并公开征集威胁信息线索的公告](https://mp.weixin.qq.com/s?__biz=MzIwNDk0MDgxMw==&mid=2247501935&idx=1&sn=46603c4a37e00113b5e6b10c03a084af) - ICT Security Magazine - [ ] [Mirage Kitten, il nuovo arsenale di spionaggio: NightLedger e i tunnel che trasformano le vittime in relay](https://www.ictsecuritymagazine.com/notizie/mirage-kitten-nightledger/) - [ ] [Un’AI indebolisce HAWK: la crittanalisi post-quantum cambia scala](https://www.ictsecuritymagazine.com/notizie/claude-crittanalisi-hawk-post-quantum/) - [ ] [AI-BOM: l’AI Bill of Materials per sapere che cosa c’è dentro un modello](https://www.ictsecuritymagazine.com/articoli/ai-bom-ai-bill-of-materials/) - 纽创信安 - [ ] [活动预告|纽创信安邀请您共聚上海,探讨后量子密码时代的芯片安全防御之道](https://mp.weixin.qq.com/s?__biz=MzAwNTczMjAzMg==&mid=2650241931&idx=1&sn=b9869a6549f112a549e2aeac03f17747) - IT Service Management News - [ ] [Pubblicata la ISO/IEC 29151:2026 con i controlli privacy](http://blog.cesaregallotti.it/2026/07/pubblicata-la-isoiec-291512026-con-i.html) - Javvad Malik - [ ] [Still Got My Nokia Somewhere Up There](https://javvadmalik.com/2026/07/29/still-got-my-nokia-somewhere-up-there/) - SANS Internet Storm Center, InfoCON: green - [ ] [Apple Patches Everything (July 2026), (Wed, Jul 29th)](https://isc.sans.edu/diary/rss/33196) - [ ] [ISC Stormcast For Wednesday, July 29th, 2026 https://isc.sans.edu/podcastdetail/10028, (Wed, Jul 29th)](https://isc.sans.edu/diary/rss/33194) - D3Lab - [ ] [Inside an N26 Impersonation Campaign: From Vishing and Fake Control 1.0 to the Copybara Android RAT](https://www.d3lab.net/inside-an-n26-impersonation-campaign-from-vishing-and-fake-control-1-0-to-the-copybara-android-rat/) - Schneier on Security - [ ] [Measuring the Tendency of AI Agents to Go Rogue](https://www.schneier.com/blog/archives/2026/07/measuring-the-tendency-of-ai-agents-to-go-rogue.html) - [ ] [Long-Lived Vulnerability in Microsoft Secure Boot](https://www.schneier.com/blog/archives/2026/07/long-lived-vulnerability-in-microsoft-secure-boot.html) - [ ] [Measuring LLMs’ Ability to Perform Cryptanalysis](https://www.schneier.com/blog/archives/2026/07/measuring-llms-ability-to-perform-cryptanalysis.html) - GRAHAM CLULEY - [ ] [Smashing Security podcast #478: This job interview could destroy your company](https://grahamcluley.com/smashing-security-podcast-478/) - Trend Micro Research, News and Perspectives - [ ] [Tracking Over 35,000 Fake Sites in the 2026 World Cup Scam Wave](https://www.trendmicro.com/en_us/research/26/g/tracking-fake-sites-in-the-2026-world-cup-scam-wave.html) - TorrentFreak - [ ] [Vietnam Uses HiAnime Arrests As Defense Against U.S. Trade Sanctions](https://torrentfreak.com/vietnam-uses-hianime-arrests-as-defense-against-u-s-trade-sanctions/) - Instapaper: Unread - [ ] [Windows Event Log Analysis Tracking Lateral Movement](https://digitalinvestigator.blogspot.com/2026/07/windows-event-log-analysis-tracking_01829375384.html) - [ ] [Cyber security negli ospedali le linee guida Enisa cambiano le regole degli appalti](https://www.cybersecurity360.it/news/cyber-security-negli-ospedali-le-linee-guida-enisa-cambiano-le-regole-degli-appalti/) - [ ] [How to recover deleted data from your iPhone](https://blog.elcomsoft.com/2026/07/how-to-recover-deleted-data-from-your-iphone/) - [ ] [After the Signal Fix Exploring Apple's notificationAndSuggestionDB.db](https://blog.digital-forensics.it/2026/07/after-signal-fix-exploring-apples.html) - Blackhat Library: Hacking techniques and research - [ ] [Constant cyber security warnings does anyone else have this problem? I’m going to apply for TAC](https://www.reddit.com/r/blackhat/comments/1va9007/constant_cyber_security_warnings_does_anyone_else/) - Security Affairs - [ ] [Claude Mythos Shows AI Can Outpace Human Cryptography Research](https://securityaffairs.com/196265/ai/claude-mythos-shows-ai-can-outpace-human-cryptography-research.html) - [ ] [Hackers Strike Minnesota Water Utilities, One Plant Briefly Offline](https://securityaffairs.com/196246/hacking/hackers-strike-minnesota-water-utilities-one-plant-briefly-offline.html) - [ ] [ShinyHunters Claims Ernst & Young Data Breach, Threatens to Leak Stolen Data](https://securityaffairs.com/196239/data-breach/shinyhunters-claims-ernst-young-data-breach-threatens-to-leak-stolen-data.html) - [ ] [Broadcom Patches Critical VMware ESXi Vulnerability Enabling Host Code Execution](https://securityaffairs.com/196231/security/broadcom-patches-critical-vmware-esxi-vulnerability-enabling-host-code-execution.html) - [ ] [OpenAI AI Model Used JFrog Artifactory Zero-Day Before Hugging Face Breach](https://securityaffairs.com/196217/hacking/openai-ai-model-used-jfrog-artifactory-zero-day-before-hugging-face-breach.html) - [ ] [OpenAI’s Rogue AI Agent Breached Second Company, Report Says](https://securityaffairs.com/196209/ai/openais-rogue-ai-agent-breached-second-company-report-says.html) - [ ] [VPN Breach Exposes 58 Million Connection Logs Despite “No-Logs” Claims](https://securityaffairs.com/196197/security/vpn-breach-exposes-58-million-connection-logs-despite-no-logs-claims.html) - www.theregister.com - Articles - [ ] [Closed models refuse to help researcher swat Linux bug](https://www.theregister.com/ai-and-ml/2026/07/29/closed-models-refuse-to-help-researcher-swat-linux-bug/5280647) - [ ] [Word worm crawls into Copilot, spreads chaos](https://www.theregister.com/security/2026/07/29/word-worm-crawls-into-copilot-spreads-chaos/5280588) - [ ] [Iran-linked CyberAv3ngers suspected in attacks on Minnesota water systems](https://www.theregister.com/security/2026/07/29/iran-linked-cyberav3ngers-suspected-in-attacks-on-minnesota-water-systems/5280357) - [ ] [America bans imported robots due to supply chain and security risks](https://www.theregister.com/security/2026/07/29/america-bans-imported-robots-due-to-supply-chain-and-security-risks/5280145) - The Hacker News - [ ] [Critical Rails Flaw Could Let Unauthenticated Attackers Read Server Files via Image Uploads](https://thehackernews.com/2026/07/critical-rails-flaw-could-let.html) - [ ] [Ruflo MCP Flaw Lets Unauthenticated Attackers Run Commands and Poison AI Memory](https://thehackernews.com/2026/07/ruflo-mcp-flaw-lets-unauthenticated.html) - [ ] [Three Critical VMware Flaws Allow Auth Bypass, Code Execution, and VM Escape](https://thehackernews.com/2026/07/three-critical-vmware-flaws-allow-auth.html) - [ ] [Coordinated Cyberattack Targets 30+ Minnesota Water Systems as One Plant Goes Offline](https://thehackernews.com/2026/07/coordinated-cyberattack-targets-30.html) - [ ] [Nine-Year Fraud Campaign Clones Russian Company Sites to Steal Advance Payments](https://thehackernews.com/2026/07/nine-year-fraud-campaign.html) - [ ] [Mythos Asks the Right Question. It Doesn't Answer It.](https://thehackernews.com/2026/07/mythos-asks-right-question-it-doesnt.html) - [ ] [Researchers Show a Single Malicious Webpage Visit Can Compromise Tor Browser](https://thehackernews.com/2026/07/researchers-show-single-malicious.html) - [ ] [73% of Organizations Say They Are Not Fully Ready for a Major Cyberattack](https://thehackernews.com/2026/07/73-of-organizations-say-they-are-not.html) - [ ] [Russia Charges Telegram Founder Pavel Durov With Aiding Terrorist Activity](https://thehackernews.com/2026/07/russia-charges-telegram-founder-pavel.html) - [ ] [Public PoC Released for Exploited Check Point SmartConsole Authentication Bypass](https://thehackernews.com/2026/07/rapid7-releases-poc-for-exploited-check.html) - [ ] [OpenAI Agent Used Exposed Credentials Across Four Services During Hugging Face Breach](https://thehackernews.com/2026/07/openai-agent-used-exposed-credentials.html) - [ ] [New Gitea RCE Lets Repository Writers Plant a Git Hook to Run Shell Commands](https://thehackernews.com/2026/07/new-gitea-rce-lets-repository-writers.html) - [ ] [Flying Eagle Android RAT Traces Found on 170 Servers as Source Code Circulates](https://thehackernews.com/2026/07/flying-eagle-android-rat-traces-found.html) - [ ] [Two Compromised joyfill npm Packages Run RAT When Imported Into Node.js](https://thehackernews.com/2026/07/two-compromised-joyfill-npm-packages.html) - Qualys Security Blog - [ ] [Operationalize AI Governance Across Shadow GenAI, MCP, and Agentic Workloads with Qualys TotalAI](https://blog.qualys.com/category/product-tech) - Deeplinks - [ ] [🏃 Fitness Tracker Privacy Fails | EFFector 38.14](https://www.eff.org/deeplinks/2026/07/fitness-tracker-privacy-fails-effector-3814) - Security Weekly Podcast Network (Audio) - [ ] [Transparency, The Key To Team Motivation For Remote Workers - Charles Gaudet - BSW #458](http://sites.libsyn.com/18678/transparency-the-key-to-team-motivation-for-remote-workers-charles-gaudet-bsw-458)
每日安全资讯(2026-07-30)